From dda722f192bd666ad52e995837dee86e91abcab9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 24 Apr 2023 15:57:35 +0000 Subject: [PATCH] Publish Advisories GHSA-jhm9-h84h-rw83 GHSA-3wx7-46ch-7rq2 GHSA-8gq9-2x98-w8hf GHSA-vvpx-j8f3-3w6h GHSA-mwq8-fjpf-c2gr GHSA-2ccf-ffrj-m4qw GHSA-4m3m-ppvx-xgw9 GHSA-833c-xh79-p429 GHSA-f4v8-58f6-mwj4 GHSA-mj9r-fpv3-rgfx GHSA-wxmh-65f7-jcvw --- .../GHSA-jhm9-h84h-rw83.json | 4 ++++ .../GHSA-3wx7-46ch-7rq2.json | 4 ++++ .../GHSA-8gq9-2x98-w8hf.json | 6 +++++- .../GHSA-vvpx-j8f3-3w6h.json | 4 ++++ .../GHSA-mwq8-fjpf-c2gr.json | 8 ++++++++ .../GHSA-2ccf-ffrj-m4qw.json | 20 +++++++++++++++++-- .../GHSA-4m3m-ppvx-xgw9.json | 16 +++++++++++++-- .../GHSA-833c-xh79-p429.json | 4 ++-- .../GHSA-f4v8-58f6-mwj4.json | 1 + .../GHSA-mj9r-fpv3-rgfx.json | 2 +- .../GHSA-wxmh-65f7-jcvw.json | 4 ++++ 11 files changed, 65 insertions(+), 8 deletions(-) diff --git a/advisories/github-reviewed/2022/05/GHSA-jhm9-h84h-rw83/GHSA-jhm9-h84h-rw83.json b/advisories/github-reviewed/2022/05/GHSA-jhm9-h84h-rw83/GHSA-jhm9-h84h-rw83.json index 8e884699fdb..9d1511521e7 100644 --- a/advisories/github-reviewed/2022/05/GHSA-jhm9-h84h-rw83/GHSA-jhm9-h84h-rw83.json +++ b/advisories/github-reviewed/2022/05/GHSA-jhm9-h84h-rw83/GHSA-jhm9-h84h-rw83.json @@ -67,6 +67,10 @@ "type": "WEB", "url": "https://github.com/phpbb/phpbb-app/commit/efc0a146bf12125eeb71d00470af774326a7bf0a" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/phpbb/phpbb/CVE-2020-8226.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/phpbb/phpbb-app" diff --git a/advisories/github-reviewed/2022/07/GHSA-3wx7-46ch-7rq2/GHSA-3wx7-46ch-7rq2.json b/advisories/github-reviewed/2022/07/GHSA-3wx7-46ch-7rq2/GHSA-3wx7-46ch-7rq2.json index 4b9ed9a5a76..b288c6d008d 100644 --- a/advisories/github-reviewed/2022/07/GHSA-3wx7-46ch-7rq2/GHSA-3wx7-46ch-7rq2.json +++ b/advisories/github-reviewed/2022/07/GHSA-3wx7-46ch-7rq2/GHSA-3wx7-46ch-7rq2.json @@ -103,6 +103,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20220715-0011/" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230420-0008/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5343" diff --git a/advisories/github-reviewed/2022/09/GHSA-8gq9-2x98-w8hf/GHSA-8gq9-2x98-w8hf.json b/advisories/github-reviewed/2022/09/GHSA-8gq9-2x98-w8hf/GHSA-8gq9-2x98-w8hf.json index f5aca18a9fa..8e458235dab 100644 --- a/advisories/github-reviewed/2022/09/GHSA-8gq9-2x98-w8hf/GHSA-8gq9-2x98-w8hf.json +++ b/advisories/github-reviewed/2022/09/GHSA-8gq9-2x98-w8hf/GHSA-8gq9-2x98-w8hf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8gq9-2x98-w8hf", - "modified": "2022-12-19T14:43:11Z", + "modified": "2023-04-24T15:56:18Z", "published": "2022-09-23T20:31:15Z", "aliases": [ "CVE-2022-1941" @@ -109,6 +109,10 @@ "type": "PACKAGE", "url": "https://github.com/protocolbuffers/protobuf" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00019.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBAUKJQL6O4TIWYBENORSY5P43TVB4M3/" diff --git a/advisories/github-reviewed/2023/02/GHSA-vvpx-j8f3-3w6h/GHSA-vvpx-j8f3-3w6h.json b/advisories/github-reviewed/2023/02/GHSA-vvpx-j8f3-3w6h/GHSA-vvpx-j8f3-3w6h.json index c76faee14bf..42b98dd40f6 100644 --- a/advisories/github-reviewed/2023/02/GHSA-vvpx-j8f3-3w6h/GHSA-vvpx-j8f3-3w6h.json +++ b/advisories/github-reviewed/2023/02/GHSA-vvpx-j8f3-3w6h/GHSA-vvpx-j8f3-3w6h.json @@ -68,6 +68,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RLBQ3A7ROLEQXQLXFDLNJ7MYPKG5GULE/" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XX3IMUTZKRQ73PBZM4E2JP4BKYH4C6XE/" + }, { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2023-1571" diff --git a/advisories/github-reviewed/2023/03/GHSA-mwq8-fjpf-c2gr/GHSA-mwq8-fjpf-c2gr.json b/advisories/github-reviewed/2023/03/GHSA-mwq8-fjpf-c2gr/GHSA-mwq8-fjpf-c2gr.json index afed58b77fe..ccae0020fab 100644 --- a/advisories/github-reviewed/2023/03/GHSA-mwq8-fjpf-c2gr/GHSA-mwq8-fjpf-c2gr.json +++ b/advisories/github-reviewed/2023/03/GHSA-mwq8-fjpf-c2gr/GHSA-mwq8-fjpf-c2gr.json @@ -52,9 +52,17 @@ "type": "PACKAGE", "url": "https://github.com/matrix-org/matrix-js-sdk" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00027.html" + }, { "type": "WEB", "url": "https://matrix.org/blog/2023/03/28/security-releases-matrix-js-sdk-24-0-0-and-matrix-react-sdk-3-69-0" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5392" } ], "database_specific": { diff --git a/advisories/github-reviewed/2023/04/GHSA-2ccf-ffrj-m4qw/GHSA-2ccf-ffrj-m4qw.json b/advisories/github-reviewed/2023/04/GHSA-2ccf-ffrj-m4qw/GHSA-2ccf-ffrj-m4qw.json index 4f002ae49a4..d70a76ef043 100644 --- a/advisories/github-reviewed/2023/04/GHSA-2ccf-ffrj-m4qw/GHSA-2ccf-ffrj-m4qw.json +++ b/advisories/github-reviewed/2023/04/GHSA-2ccf-ffrj-m4qw/GHSA-2ccf-ffrj-m4qw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2ccf-ffrj-m4qw", - "modified": "2023-04-21T22:32:47Z", + "modified": "2023-04-24T15:56:27Z", "published": "2023-04-21T22:32:47Z", "aliases": [ "CVE-2023-29020" @@ -59,14 +59,30 @@ "type": "WEB", "url": "https://github.com/fastify/fastify-passport/security/advisories/GHSA-2ccf-ffrj-m4qw" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29020" + }, + { + "type": "WEB", + "url": "https://github.com/fastify/fastify-passport/commit/07c90feab9cba0dd4779e47cfb0717a7e2f01d3d" + }, + { + "type": "WEB", + "url": "https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html#synchronizer-token-pattern" + }, { "type": "PACKAGE", "url": "https://github.com/fastify/fastify-passport" + }, + { + "type": "WEB", + "url": "https://owasp.org/www-community/attacks/csrf" } ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": true, diff --git a/advisories/github-reviewed/2023/04/GHSA-4m3m-ppvx-xgw9/GHSA-4m3m-ppvx-xgw9.json b/advisories/github-reviewed/2023/04/GHSA-4m3m-ppvx-xgw9/GHSA-4m3m-ppvx-xgw9.json index 6d3d83db953..43dab8cdbb1 100644 --- a/advisories/github-reviewed/2023/04/GHSA-4m3m-ppvx-xgw9/GHSA-4m3m-ppvx-xgw9.json +++ b/advisories/github-reviewed/2023/04/GHSA-4m3m-ppvx-xgw9/GHSA-4m3m-ppvx-xgw9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4m3m-ppvx-xgw9", - "modified": "2023-04-21T22:33:30Z", + "modified": "2023-04-24T15:56:25Z", "published": "2023-04-21T22:33:30Z", "aliases": [ "CVE-2023-29019" @@ -59,14 +59,26 @@ "type": "WEB", "url": "https://github.com/fastify/fastify-passport/security/advisories/GHSA-4m3m-ppvx-xgw9" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29019" + }, + { + "type": "WEB", + "url": "https://github.com/fastify/fastify-passport/commit/43c82c321db58ea3e375dd475de60befbfcf2a11" + }, { "type": "PACKAGE", "url": "https://github.com/fastify/fastify-passport" + }, + { + "type": "WEB", + "url": "https://owasp.org/www-community/attacks/Session_fixation" } ], "database_specific": { "cwe_ids": [ - + "CWE-384" ], "severity": "HIGH", "github_reviewed": true, diff --git a/advisories/github-reviewed/2023/04/GHSA-833c-xh79-p429/GHSA-833c-xh79-p429.json b/advisories/github-reviewed/2023/04/GHSA-833c-xh79-p429/GHSA-833c-xh79-p429.json index be30459869f..71462b2cfd1 100644 --- a/advisories/github-reviewed/2023/04/GHSA-833c-xh79-p429/GHSA-833c-xh79-p429.json +++ b/advisories/github-reviewed/2023/04/GHSA-833c-xh79-p429/GHSA-833c-xh79-p429.json @@ -1,10 +1,10 @@ { "schema_version": "1.4.0", "id": "GHSA-833c-xh79-p429", - "modified": "2023-04-21T19:42:10Z", + "modified": "2023-04-24T15:57:13Z", "published": "2023-04-21T19:42:10Z", "aliases": [ - + "CVE-2023-30622" ], "summary": "A potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation", "details": "## Summary:\nA potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation.\n## Detailed analysis:\nThe clusternet has a deployment called cluster-hub inside the clusternet-system Kubernetes namespace, which runs on worker nodes\nrandomly. The deployment has a service account called clusternet-hub, which has a cluster role called clusternet:hub via cluster role binding. The clusternet:hub cluster role has \"*\" verbs of \"*.*\" resources. Thus, if a malicious user can access the worker node which runs the clusternet, he/she can leverage the service account to do malicious actions to critical system resources. For example, he/she can leverage the service account to get ALL secrets in the entire cluster, resulting in cluster-level privilege escalation.", diff --git a/advisories/github-reviewed/2023/04/GHSA-f4v8-58f6-mwj4/GHSA-f4v8-58f6-mwj4.json b/advisories/github-reviewed/2023/04/GHSA-f4v8-58f6-mwj4/GHSA-f4v8-58f6-mwj4.json index befdecc2cab..d07ba7b96e7 100644 --- a/advisories/github-reviewed/2023/04/GHSA-f4v8-58f6-mwj4/GHSA-f4v8-58f6-mwj4.json +++ b/advisories/github-reviewed/2023/04/GHSA-f4v8-58f6-mwj4/GHSA-f4v8-58f6-mwj4.json @@ -97,6 +97,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-94", "CWE-95" ], "severity": "CRITICAL", diff --git a/advisories/github-reviewed/2023/04/GHSA-mj9r-fpv3-rgfx/GHSA-mj9r-fpv3-rgfx.json b/advisories/github-reviewed/2023/04/GHSA-mj9r-fpv3-rgfx/GHSA-mj9r-fpv3-rgfx.json index f2d49e33def..e43d27d9bcb 100644 --- a/advisories/github-reviewed/2023/04/GHSA-mj9r-fpv3-rgfx/GHSA-mj9r-fpv3-rgfx.json +++ b/advisories/github-reviewed/2023/04/GHSA-mj9r-fpv3-rgfx/GHSA-mj9r-fpv3-rgfx.json @@ -48,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": true, diff --git a/advisories/github-reviewed/2023/04/GHSA-wxmh-65f7-jcvw/GHSA-wxmh-65f7-jcvw.json b/advisories/github-reviewed/2023/04/GHSA-wxmh-65f7-jcvw/GHSA-wxmh-65f7-jcvw.json index e67c970eef3..09f803d77b0 100644 --- a/advisories/github-reviewed/2023/04/GHSA-wxmh-65f7-jcvw/GHSA-wxmh-65f7-jcvw.json +++ b/advisories/github-reviewed/2023/04/GHSA-wxmh-65f7-jcvw/GHSA-wxmh-65f7-jcvw.json @@ -67,6 +67,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29197" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/guzzlehttp/psr7/CVE-2023-29197.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/guzzle/psr7"